Taking work now — the first look is freeDrives posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
BLKBitLocker Data Recovery 0800 6890668 Price my job
BLK / How the drive was locked / Recovery key, or 48-digit password

48-digit recovery key · recovery password · key ID · the master spare · escrow

The BitLocker recovery key. Forty-eight digits that open the drive when everything else has failed, if you can find them.

The 48-digit recovery key is the most important thing in all of BitLocker, and the first thing to find in almost every lockout. It is a protector like any other, but a special one: it unlocks the Volume Master Key directly, so it opens the drive whatever has happened to the TPM, the PIN, the password or the startup key. A Windows update, a cleared TPM, a new motherboard, a forgotten PIN: the recovery key gets you past all of them, because it was designed as the master spare for exactly these moments. It is eight groups of six digits, shown on the blue recovery screen and stored, usually automatically, in your Microsoft account, your organisation's directory, or a file you saved when BitLocker was turned on. With it in hand, even a drive that has physically failed is fully recoverable: we image the failed drive and decrypt the image with your key. Without it, and with no other protector you can open, a modern BitLocker drive cannot be opened at all. This page is about what the key is and where to find it; if you have it already, you are most of the way home.

Owner-only, proof requiredFree first look£800 + VAT, one diskNo fix, no fee on the balance

Rather talk it through? An engineer answers the bench line
0800 6890668

Stop before you reinstall or reformat anything. If the machine is at the BitLocker recovery screen, the data is intact behind the key; reinstalling Windows, reformatting the drive or clearing the TPM again will not get you in and can overwrite what is there. Do not keep typing the wrong key until a device locks you out. If the machine is still running and unlocked, do not shut it down before you have read the lost-password pages. Find your recovery key first, and send nothing until you have.

Everywhere the key could be, and how to tell which is yours.

The recovery key is almost always escrowed somewhere when BitLocker is switched on. The finder page is the full walk-through; in short, look in your personal Microsoft account at account.microsoft.com/devices/recoverykey or aka.ms/myrecoverykey; a work or school account in Microsoft Entra ID at aka.ms/aadrecoverykey; on-premises Active Directory, as the msFVE-RecoveryPassword attribute, read by IT with the recovery password viewer; Intune or MBAM for managed machines; and any printout, saved text file, or .BEK file on a USB stick you made at setup.

If several keys are stored, the recovery screen tells you which you need: it shows a key ID, the first eight characters of the identifier for the specific key that drive wants. Match that to the ID shown beside each stored key and you have the right one. If you send us the key ID, we can tell you which stored key matches and help you confirm it.

Microsoft states plainly that it cannot access or reset a lost BitLocker recovery key. The key exists only where it was escrowed or saved; if it is in none of those places, it cannot be recreated, and on a modern AES-256-XTS drive with no other openable protector the data cannot be recovered. That is the one hard limit, and it is why finding the key, or never losing it, matters so much.

Why the recovery key is the whole game.

It opens the Volume Master Key directlyUnlike a PIN or password, which protect the key behind the hardware, the recovery key unlocks the VMK on its own. That is why it works when the TPM has changed, the PIN is forgotten or the password is lost: it does not depend on any of them, only on the 48 digits.
With the key, a failed drive is recoverableA recovery key turns a failed-drive job into an ordinary one. We image the failed or corrupt drive at the sector level, then decrypt the image with your key. The failure is a hardware problem we solve the usual way; the encryption is no obstacle once the key is in hand.
The key ID stops you trying the wrong onePeople with several devices often have several keys, and typing the wrong 48 digits gets nowhere. The key ID on the recovery screen, those first eight characters, identifies the exact key the drive wants, so you can match it to the right stored key instead of guessing.
No key, no other protector, no entryThe flip side of the key's power is the hard limit: if it is lost and no PIN, password or memory capture can open the drive, the data stays encrypted. There is no backdoor. This is the case the honest pages here prepare you for, and the reason to find and keep the key.

What you see, and what is behind it.

Describe yours to us →
What you see What is usually behind it Where that leaves you
The recovery screen shows a key IDThe drive is telling you which key it wantsMatch the ID to your stored keys; use that one
Key found; drive is healthyOnly the lockout stood in the wayEnter it; the drive opens; no work needed
Key found; drive has failedA hardware job with the encryption solvedImaged, then decrypted from the clone
Several keys, none seems to workProbably the wrong key for this driveThe key ID identifies the right one
Key genuinely lost, no other protectorNothing left that can open the VMKNot recoverable; we say so at the free look

From the drive arriving to your files going back.

Work we have closed →
01

Logged the day it lands, and the first look costs nothing Free

A number goes on the parcel and the drive the day it is opened, matched to your enquiry by the booking sheet inside. Before anything is read we check the proof of ownership you sent. The drive is then connected through a write blocker, read-only, and examined: whether it is a healthy drive behind a lost key, or a failing drive behind a known key, is settled here, and so is whether what you want is possible. That first look is free, and you may stop at it owing nothing.

Nothing to pay for lookingProof of ownership checked firstRead-only, nothing written to the drive
02

Imaged at the sector level, before anything else

A drive that answers at all is imaged in full on a hardware imager, behind a write blocker, weak areas last, with a map kept of what could not be read. The image is a copy of the encrypted sectors, so it is useless to anyone without your key, which is a privacy gain in itself. Every later step is done on the image. The original drive is never decrypted, never written to, and never worked on directly.

Sector by sector, behind a write blockerNothing written to the original
03

The physical fault repaired on the clone, when there is one

A drive that has failed, that reads slowly or that drops out is stabilised and imaged in passes; a mechanically failed disk is repaired and read on the bench, a dead SSD controller read at the chip level, before any decryption is attempted. The aim at this stage is one clean image of the encrypted volume to decrypt from. Where the drive is healthy and the problem is only the key, this stage is skipped.

Mechanical and chip-level work where neededOne clean encrypted image to work from
04

The image decrypted with your key or password

With your recovery key, recovery password or the drive's password, the image is unlocked: the protector releases the Volume Master Key, the VMK releases the Full Volume Encryption Key, and the volume is decrypted from the clone. Where the metadata or header is damaged, repair-bde and the key package rebuild it at the block level onto a separate target. Where the key is lost but a memory image or hibernation file is available, the Volume Master Key is extracted from it with Passware. Without a key, a password to attack, or a memory capture, the volume cannot be opened, and you are told so at the free look.

Protector → VMK → FVEK → volumeDecrypted from the clone, never the original
05

The file system rebuilt, and the list before the bill

Once the volume is open it is an ordinary NTFS or exFAT file system, and any damage in it is repaired on the image and the files recovered. What was recovered is listed for you first, and only then does a bill exist. The files go home on fresh media. The original drive is returned, or securely destroyed at your request; we never send the key and the data by the same route.

Files listed before any invoiceFresh media, supplied with the job3–7 days at the bench

From the bench

  • The recovery screen's eight characters are the key ID, not the key. They tell you, and us, which 48-digit key the drive wants when you have more than one.
  • Once you are back in, save the key somewhere you will find it, and consider printing it. The next lockout is much easier when the key is to hand.
  • With the key, even a dead drive is recoverable. Do not assume a failed encrypted drive is lost; the key plus imaging is a routine job.

Eight characters of key ID on the recovery screen identify which 48-digit key the drive wants, when you have more than one.

One job, followed all the way through.

UK · BLK-2026-0704JOB LOGGED ✓

A Surface laptop whose SSD was failing and which held a 48-digit key the owner had wisely printed, with a postgraduate thesis and its research on it

This is the case the recovery key is made for. The drive was dropping out and would not boot. With ownership confirmed, we imaged the failing SSD in passes behind a write blocker, getting a complete image of the encrypted volume, then decrypted the image with the printed recovery key. The thesis and every source came back. The drive's failure was the whole problem; the key made the encryption a non-issue.

100% recovered; key plus imaging5 days at the bench
Illustrative example — replace with a genuine case

What helps, and what harms.

Do this much first

  • Find the 48-digit key first; it opens almost any lockout
  • Match the key ID on the screen to the right stored key
  • Keep the key safe once you are back in
  • Send proof of ownership if the drive needs lab work

What sets us back

  • Typing the wrong key from another device repeatedly
  • Assuming a failed encrypted drive is unrecoverable; with the key it is not
  • Reinstalling Windows while the key is still findable
  • Believing anyone who offers to recreate a lost key; it cannot be done
We recover BitLocker drives for the people who own them. Before any work begins we ask for proof that the drive is yours or that you are authorised to have it recovered: a purchase receipt, the device serial, a letter on company letterhead for a work machine, or written authorisation from the owner, together with photo ID and a signed authorisation. It is a condition of the work, not a formality, and it is what keeps the service on the right side of the Computer Misuse Act. A drive with no proof of ownership is returned unread.

Questions answered before you commit.

What exactly is the BitLocker recovery key?

A 48-digit number, eight groups of six digits, that unlocks the drive's master key directly. It is created when BitLocker is switched on and stored in your Microsoft account, your organisation's directory, or a file you saved. It opens the drive whatever other protector has failed, which is why it is the first thing to find.

Is the recovery key the same as the recovery password?

Yes, in normal use. Microsoft calls the 48-digit number the recovery password and uses recovery key for a .BEK key file, but almost everyone means the 48 digits when they say recovery key, and that is what the recovery screen asks for.

Can my data be recovered from a failed drive if I have the key?

Yes, and this is the best case. We image the failed or corrupt drive at the sector level, then decrypt the image with your key. The hardware failure is solved the usual way and the encryption is no obstacle once the key is in hand.

What if I have lost the recovery key completely?

Then the question becomes whether any other protector can open the drive, a weak password, a short PIN with a memory capture, an escrow copy you have forgotten. If none can, a modern AES-256 BitLocker drive cannot be opened by anyone, because Microsoft cannot reset a lost key and the encryption cannot be brute-forced. We tell you honestly at the free look.

What does it cost?

If you have the key and the drive is healthy, entering it costs nothing and you may not need us. If the drive has failed, single-disk recovery and decryption is £800 + VAT, 50% non-refundable on acceptance and 50% no fix, no fee.

The data is behind the key, not gone.

Looking at it is free, and it begins with the one question that decides everything: do you have the recovery key or password, or can you retrieve it. Tell us what the recovery screen says and what the drive has done, send the proof that it is yours, and back comes a straight account of what is possible and the one price to do it. Until then, reinstall nothing and reformat nothing.

0800 6890668